TF-1850352
high
📛 Threat Title
RevStealer: Domain that is used for botnet Command&control (C&C) deploy.works-rhythm8.click
Description
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 100. First seen: 2026-07-14 14:44:15 UTC. Reporter: Myrtus0x0. Tags: exe, RevStealer.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
104.21.28.109
IOC database
- Type
- ipv4
- Value
104.21.28.109- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Resolved from domain deploy.works-rhythm8.click
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
172.67.145.220
IOC database
- Type
- ipv4
- Value
172.67.145.220- First seen
- Last seen
- Attached to this threat
- Appears in
- 2 threats
- Description
- Resolved from domain deploy.works-rhythm8.click
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
domain
deploy.works-rhythm8.click
UrlVoid 3 / 35
IOC database
- Type
- domain
- Value
deploy.works-rhythm8.click- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Ingested from IOC source: https://threatfox.abuse.ch/downloads/hostfile/
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
- Malpedia profile ThreatFox IOCs
-
ThreatFox IOC page
ThreatFox IOCs
Indicator that identifies a botnet command&control server (C&C). IOC type: Domain that is used for botnet Command&control (C&C). Attributed malware: RevStealer. Confidence: 100. First seen: 2026-07-14 14:44:15 UTC. Reporter: Myrtus0x0. Tags: exe, RevStealer.
- External reference ThreatFox IOCs
Remediations (10)
-
web:blog.pulsedive.com
Dive into a technical primer on the modern botnet landscape - including the evolution of Mirai-based botnets , capabilities, and recent enforcement actions.
-
web:clickpatrol.com
DNS sinkholing is a clever technique to disrupt botnet communication by rerouting traffic that typically goes to a Command and Control server. How it works: A sinkhole server mimics a legitimate DNS server. When a bot-infected machine tries to contact its C2 domain , it is silently rerouted to the sinkhole.
-
web:help.bitsighttech.com
⇤ Compromised Systems Findings The Botnet Infections risk vector is an indication of a host participating in a botnet , including active bots and Command and Control servers ( C&C servers). Navi...
-
web:networkthreatdetection.com
Learn how recognizing botnet command and control patterns reveals hidden threats and keeps your network safe from malicious attacks.
-
web:threatfox.abuse.ch
RevStealer IOC: deploy.works-rhythm8.click ( domain ) You are viewing the ThreatFox database entry for domain deploy.works-rhythm8.click.
-
web:www.bsi.bund.de
Current bot overviews This page is designed to give you an overview of the most common botnet families currently in existence. We provide a summary of the type of infection, the systems affected and what action you can take to clean up your system. The list is non-exhaustive and is being updated all the time.
-
web:www.geeksforgeeks.org
At this point, the infected devices are connected and controlled remotely through a central command-and-control (C&C) server. The attacker can command these devices, to perform tasks like sending spam, participating in distributed denial-of-service (DDoS) attacks, or stealing data. How to Prevent Botnet Attacks?
-
web:www.radware.com
Botnet detection involves identifying networks of infected computers controlled by attackers to perform malicious activities. Early detection can prevent substantial damage to systems and networks, requiring techniques to monitor and analyze behavior patterns, traffic anomalies, and communication protocols.
-
web:www.spamhaus.org
Overall botnet command control (C&C) activity decreased marginally by -4% between July and December last year. China dominated the Top 20 charts with increased botnet C&C activity across domain registrars and networks, ranking #1 globally for hosting botnet C&C servers. Download the latest report to learn more.
-
web:www.spamhaus.org
Once active, it can execute commands, steal data, deploy additional malware, and maintain persistence through scheduled tasks and encrypted communication with its command-and-control servers.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.